• English
  • Deutsch
  • Log In
    or
  • Research Outputs
  • Projects
  • Researchers
  • Institutes
  • Statistics
Repository logo
Fraunhofer-Gesellschaft
  1. Home
  2. Fraunhofer-Gesellschaft
  3. Konferenzschrift
  4. Distributed usage control enforcement through trusted platform modules and SGX enclaves
 
  • Details
  • Full
Options
2018
Conference Paper
Titel

Distributed usage control enforcement through trusted platform modules and SGX enclaves

Abstract
In the light of mobile and ubiquitous computing, sharing sensitive information across different computer systems has become an increasingly prominent practice. This development entails a demand of access control measures that can protect data even after it has been transferred to a remote computer system. In order to address this problem, sophisticated usage control models have been developed. These models include a client side reference monitor (CRM) that continuously enforces protection policies on foreign data. However, it is still unclear how such a CRM can be properly protected in a hostile environment. The user of the data on the client system can influence the client's state and has physical access to the system. Hence technical measures are required to protect the CRM on a system, which is legitimately used by potential attackers. Existing solutions utilize Trusted Platform Modules (TPMs) to solve this problem by establishing an attestable trust anchor on the client. However, the resulting protocols have several drawbacks that make them infeasible for practical use. This work proposes a reference monitor implementation that establishes trust by using TPMs along with Intel SGX enclaves. First we show how SGX enclaves can realize a subset of the existing usage control requirements. Then we add a TPM to establish and protect a powerful enforcement component on the client. Ultimately this allows us to technically enforce usage control policies on an untrusted remote system.
Author(s)
Wagner, P.
Birnstill, Pascal
Beyerer, Jürgen
Hauptwerk
SACMAT 2018, 23nd ACM on Symposium on Access Control Models and Technologies. Proceedings
Konferenz
Symposium on Access Control Models and Technologies (SACMAT) 2018
DOI
10.1145/3205977.3205990
File(s)
N-506606.pdf (505.78 KB)
Language
English
google-scholar
Fraunhofer-Institut für Optronik, Systemtechnik und Bildauswertung IOSB
Tags
  • usage control

  • access control

  • trusted reference mon...

  • trusted platform modu...

  • SGX

  • secure remote computa...

  • Cookie settings
  • Imprint
  • Privacy policy
  • Api
  • Send Feedback
© 2022